
Kaspersky has warned of a spying campaign involving malicious apps hosted on Google Play. The apps are spying on and stealing data users Android.
On Tuesday, the company's researchers said that the espionage campaign, dubbed PhantomLance (the name of the trojan used), has been going on for four years and is ongoing.
According to the research team, “dozens” of malicious apps linked to PhantomLance and hosting a new Trojan have been discovered on Google Play, the official app store for devices . Additionally, malicious apps have been found on the APK download site, APKpure.
In July 2019, Doctor Web researchers published a study about a new Trojan hiding in an application on Google Play and appearing as OpenGL Plugin.
In reality, the malicious application installs a backdoor and starts stealing user.
Kaspersky says that a similar sample of this Trojan was found on Google Play and uses high-level encryption, while also having the ability to adapt the malicious payload depending on the mobile device's environment. This indicates that PhantomLance is a dangerous espionage campaign.

PhantomLance malware, of which many variants have been identified, has the basic functions of a spyware ( removal and theft of user information, such as call logs, contacts, GPS data, SMS messages, and device model and operating system information).
The Trojan can create a backdoor to transfer stolen data to the hackers' command-and-control (C2) server, as well as deploy additional malicious payloads.
Kaspersky believes that an APT (Advanced Persistent Threat) group . It bases this guess on its careful steps and ability to cover its tracks. In “almost every case,” the group says, fake developer profiles were created and linked to GitHub accounts. To avoid detection, the first version of each app, uploaded to Google Play or APKpure, did not contain malicious code.
“With subsequent updates, the applications received malicious payloads and code to execute those payloads,” Kaspersky says.
Researchers detected around 300 attempts to infect Android, in countries including India, Vietnam, Bangladesh and Indonesia.
Attributing it to a specific hacking group is not an easy task. However, the PhantomLance espionage campaign may be linked to the APT group, OceanLotus, also known as APT32.
Kaspersky says (not with absolute certainty) that OceanLotus is behind the payloads, because at least 20% of the codebase is similar to previous cyberattacks by the group targeting Android users
OceanLotus has been active since 2013 and has been linked to espionage campaigns targeting the governments of Vietnam and China. Recently, such an espionage campaign targeted the Chinese Ministry of Emergency Management and the Wuhan government. The hackers wanted to obtain information related to the COVID-19 pandemic .
Kaspersky reported all the malicious apps found and Google is removing them from Google Play.
"PhantomLance hackers managed to bypass Google Play and other store filters several times, using advanced techniques to achieve their goals," said Alexey Firsh, a researcher at Kaspersky.
